Vulnerabilities > CVE-2019-10951 - Out-of-bounds Write vulnerability in Deltaww Cncsoft Screeneditor 1.00.88
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
References
- http://www.securityfocus.com/bid/107989
- http://www.securityfocus.com/bid/107989
- https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01
- https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01
- https://www.zerodayinitiative.com/advisories/ZDI-19-405/
- https://www.zerodayinitiative.com/advisories/ZDI-19-405/
- https://www.zerodayinitiative.com/advisories/ZDI-19-408/
- https://www.zerodayinitiative.com/advisories/ZDI-19-408/